• Tim Peters's avatar
    SF bug 1003471: Python 1.5.2 security vulnerability · 8484fbf0
    Tim Peters yazdı
    This was probably fixed in rev 1.32 of getpath.c, but there are so
    many paths thru the code that invoke joinpath() it's not at all
    obvious that it *is* fixed.  It doesn't help confidence that a crucial
    precondition for calling joinpath() was neither documented nor verified.
    It is now, and joinpath() will barf with a fatal error now rather than
    overrun the buffer, if the precondition isn't met.
    
    Note that this patch only changes the Windows flavor.  I attached another
    patch to the bug report for the POSIX flavor (which I can't test
    conveniently).
    8484fbf0
Adı
Son kayıt (commit)
Son güncelleme
Demo Loading commit data...
Doc Loading commit data...
Grammar Loading commit data...
Include Loading commit data...
Lib Loading commit data...
Mac Loading commit data...
Misc Loading commit data...
Modules Loading commit data...
Objects Loading commit data...
PC Loading commit data...
PCbuild Loading commit data...
Parser Loading commit data...
Python Loading commit data...
RISCOS Loading commit data...
Tools Loading commit data...
.cvsignore Loading commit data...
.hgtags Loading commit data...
LICENSE Loading commit data...
Makefile.pre.in Loading commit data...
README Loading commit data...
aclocal.m4 Loading commit data...
configure Loading commit data...
configure.in Loading commit data...
install-sh Loading commit data...
pyconfig.h.in Loading commit data...
setup.py Loading commit data...